LiveActive security incident?Get immediate response
CVE archive

June 2015

Browse CVE records published in June 2015, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 592 matching CVEs · Page 4 of 12.

Unknown · CVSS Not scored

CVE-2015-4395: The HybridAuth Social Login module 7.x-2.x before 7.x-2.10 for Drupal stores passwords in plaintext when th...

The HybridAuth Social Login module 7.x-2.x before 7.x-2.10 for Drupal stores passwords in plaintext when the "Ask user for a password when registering" option is enabled, which allows remote authenticated users with certain permissions to obtain sensitive information by leveraging access to the database.

Published Jun 15, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-4427: Multiple cross-site scripting (XSS) vulnerabilities in Test/WorkArea/workarea.aspx in Ektron Content Manage...

Multiple cross-site scripting (XSS) vulnerabilities in Test/WorkArea/workarea.aspx in Ektron Content Management System (CMS) before 9.10 SP1 (Build 9.1.0.184.1.114) allow remote authenticated users to inject arbitrary web script or HTML via the (1) page, (2) action, (3) folder_id, or (4) LangType parameter.

Published Jun 9, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-4381: Cross-site scripting (XSS) vulnerability in the Invoice module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7....

Cross-site scripting (XSS) vulnerability in the Invoice module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allows remote authenticated users with the "Administer own invoices" permission to inject arbitrary web script or HTML via unspecified vectors involving nodes of the "Invoice" content type.

Published Jun 15, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-4387: Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Password Policy module...

Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Password Policy module 6.x-1.x before 6.x-1.11 and 7.x-1.x before 7.x-1.11 for Drupal, when a site has a policy that uses the username constraint, allows remote attackers to inject arbitrary web script or HTML via a crafted username that is imported from an external source.

Published Jun 15, 2015 · Updated Aug 6, 2024